From ed6837d1f7de634c04c730a84a0a45fb62fe6e29 Mon Sep 17 00:00:00 2001 From: Nikita Kalyazin Date: Mon, 28 Sep 2026 17:33:12 +0100 Subject: [PATCH] ci: bump github/codeql-action to v4.38.2 init, analyze and upload-sarif share one revision: the action refuses a run whose analyze half was loaded from a different version than its init half, so bumping one alone fails every CodeQL job with "Loaded a configuration file for version X, but running version Y". Dependabot files them as three pull requests, which is why this is one. ACTION_PINS moves in the same commit, the shape test asserting the workflow and the pin agree. Signed-off-by: Nikita Kalyazin --- .github/scripts/security-workflow.test.py | 2 +- .github/workflows/security.yml | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/scripts/security-workflow.test.py b/.github/scripts/security-workflow.test.py index 6d9d457..2337a08 100755 --- a/.github/scripts/security-workflow.test.py +++ b/.github/scripts/security-workflow.test.py @@ -46,7 +46,7 @@ # reproduced on this one — so a 40-hex that looks like an upstream release fetches what that fork wrote. ACTION_PINS = { "actions/checkout": "3d3c42e5aac5ba805825da76410c181273ba90b1", - "github/codeql-action": "1c5b675653bb5c22dbe9b12b556ec555138e09fd", + "github/codeql-action": "2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2", } # Pinned by value: nothing bumps a docker reference in an env:, unlike the uses: SHAs above. SCANNER_REPO = "ghcr.io/google/osv-scanner" diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 8f24b11..a7b13d6 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -33,7 +33,7 @@ jobs: persist-credentials: false - name: Initialize CodeQL - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: languages: ${{ matrix.language }} build-mode: none @@ -43,7 +43,7 @@ jobs: - ${{ matrix.pack }} - name: Analyze - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: category: "/language:${{ matrix.language }}" @@ -71,7 +71,7 @@ jobs: run: bash .github/scripts/scan.sh - name: Upload the OSV results - uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: sarif_file: results.sarif category: osv-scanner